Large-scale SMS phishing campaigns in Iran impersonated government bodies and other trusted services to lure victims to phishing sites, where they were prompted to install malicious Android applications and submit payment card details. The malware blended credential theft with mobile backdoor functions, including SMS theft, 2FA interception, contact harvesting, app hiding, and the ability to spread additional phishing messages through a botnet using Firebase Cloud Messaging.
The activity reportedly hit tens of thousands of victims and stole billions of Iranian rials, with some individuals losing the equivalent of $1,000 to $2,000. Researchers found that the operation relied on rapidly rotating phishing domains, hardcoded control panels, and in some cases leaked or poorly secured operator panels that exposed stolen victim data to third parties. The campaigns were also tied to a broader botnet-as-a-service ecosystem promoted in Iranian Telegram channels, where phishing kits and mobile campaign panels were sold to low-skill operators, helping the fraud scale and persist.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
The analysis found that phishing pages, Android kits, and control panels were being sold through Iranian Telegram channels, indicating a botnet-as-a-service ecosystem that enabled low-skill operators to run the campaigns at scale.
Poor operational security left attacker control panels and directories accessible, exposing stolen SMS, contacts, bot lists, and campaign files to third parties. One panel reportedly hosted more than 10 campaigns, and leaked data showed more than 1,000 victims installed one app in less than 10 days.
The malicious Android apps used in the campaigns functioned as backdoors that uploaded SMS messages, intercepted 2FA codes, stole contacts, hid their icons, and sent additional phishing SMS messages from infected phones. Operators controlled infected devices through Firebase Cloud Messaging and panel infrastructure.
Multiple SMS phishing campaigns in Iran impersonated government services and other trusted brands, directing victims to fake sites that collected personal and payment-card data and pushed malicious Android APKs. The campaigns reportedly affected tens of thousands of victims over a period of months and stole billions of Iranian rials.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 68 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.